What happened
Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.
How the deception worked
This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.
Sources (2)
- Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 FirmCoinDesk·coindesk.comOpen ↗
- Explained: The Munchables Hack (March 2024)Halborn·halborn.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.